<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Recent software supply chain attacks - yowers!]]></title><description><![CDATA[<p>Recent software supply chain attacks - yowers! </p><p>In March, popular open source tools Trivy and Axios were compromised with malware, and we won't know the full blast radius for months.</p><p>Axios was breached by North Korean hackers who turned it into a malware delivery vehicle for about three hours after attackers hijacked a maintainer's account and slipped a remote-access trojan (RAT) into two seemingly legitimate releases. </p><p>Trivy was hacked by a loosely knit band of hackers called TeamPCP, who injected credential-stealing malware. </p><p>"Attackers are starting to really look at the supply chain and open source packages, and figure out ways to compromise developers to deliver malware or gather data" ...  <a href="https://www.theregister.com/2026/04/11/trivy_axios_supply_chain_attacks/" rel="nofollow noopener"><span>https://www.</span><span>theregister.com/2026/04/11/tri</span><span>vy_axios_supply_chain_attacks/</span></a>  <a href="https://techhub.social/tags/Hackers" rel="tag">#<span>Hackers</span></a> <a href="https://techhub.social/tags/Malware" rel="tag">#<span>Malware</span></a> <a href="https://techhub.social/tags/Software" rel="tag">#<span>Software</span></a> <a href="https://techhub.social/tags/OpenSource" rel="tag">#<span>OpenSource</span></a> <a href="https://techhub.social/tags/SoftwareSupplyChain" rel="tag">#<span>SoftwareSupplyChain</span></a>  <a href="https://techhub.social/tags/Trojan" rel="tag">#<span>Trojan</span></a> <a href="https://techhub.social/tags/CyberSecurity" rel="tag">#<span>CyberSecurity</span></a> <a href="https://techhub.social/tags/Security" rel="tag">#<span>Security</span></a>  <a href="https://techhub.social/tags/Trivy" rel="tag">#<span>Trivy</span></a> <a href="https://techhub.social/tags/Axios" rel="tag">#<span>Axios</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://files.techhub.social/media_attachments/files/116/415/704/613/746/882/original/8e82884e9f90fc66.jpg" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/14f35487-d800-4a81-9cd1-6501af1980a9/recent-software-supply-chain-attacks-yowers</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 03:47:04 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/14f35487-d800-4a81-9cd1-6501af1980a9.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 16 Apr 2026 18:18:05 GMT</pubDate><ttl>60</ttl></channel></rss>